Quick answer
The person who used the credit card without permission is primarily responsible for the fraud and may face criminal and civil liability. Whether the cardholder, issuing bank, merchant, or another service provider must ultimately absorb the charge depends on how the card was compromised, when the issuer was notified, what the cardholder did, and whether the institutions followed their security and verification duties.
For a lost or stolen physical card, the rule is unusually strict: transactions made before the loss or theft is reported to the issuer are generally for the cardholder’s account. Once the issuer receives prompt notice, the cardholder should not remain liable for later unauthorized use.
For card-not-present fraud, account takeover, cloning, phishing, or unauthorized online charges, liability is not decided simply because the correct card details or a one-time password were used. The issuer must investigate the transaction and consider the conduct and security compliance of everyone involved.
Report the transaction immediately. Do not wait for the monthly statement or for the merchant to answer.
Who may be liable
The unauthorized user
A person who knowingly uses a stolen, lost, counterfeit, altered, cancelled, or otherwise unauthorized credit card or account credential may commit access-device fraud under the Access Devices Regulation Act, Republic Act No. 8484, as amended by Republic Act No. 11449.
Possible criminal liability can also arise from related acts such as:
- Using or trafficking in counterfeit access devices
- Using another person’s card or card information with intent to defraud
- Skimming, copying, or counterfeiting a payment card
- Fraudulently accessing a credit-card account
- Possessing or using equipment or software intended for access-device fraud
Which offense applies—and whether the evidence proves it—is a matter for law enforcement, prosecutors, and ultimately the courts. A criminal complaint does not automatically reverse the charge, so the cardholder should pursue the issuer’s dispute process at the same time.
The cardholder
A cardholder is not automatically liable for every transaction bearing the correct card number, CVV, PIN, password, or OTP. Those details are evidence relevant to the investigation, but they do not by themselves answer who initiated or knowingly approved the transaction.
There are, however, important situations in which the cardholder may bear all or part of the loss.
Lost or stolen physical card: transactions before reporting
Section 15 of the Philippine Credit Card Industry Regulation Law, Republic Act No. 10870, provides that transactions made before a lost or stolen credit card is reported to the issuer are for the cardholder’s account.
This makes the exact reporting time critical. Call the issuer’s official fraud hotline immediately, have the card blocked, and keep the reference number and timestamp.
Transactions after reporting
The Supreme Court has ruled that prompt notice of a lost or stolen card is enough to relieve the cardholder from liability for unauthorized use after notice. An issuer cannot continue charging the cardholder merely because it has not yet circulated the cancellation to its merchants. See Ermitaño v. Court of Appeals and the Court’s application of that rule in Aznar v. Citibank, N.A., G.R. No. 135149, July 25, 2006.
The issuer’s internal delay in blocking the card should not extend the cardholder’s liability after the issuer has received the report.
When the card or credentials were voluntarily shared
The outcome may be different if the cardholder:
- Gave the card to another person to use
- Shared the PIN, password, CVV, or OTP
- Approved a transaction in the banking app
- Allowed another person continuing access to the account
- Confirmed a transaction to the issuer
- Failed to report after receiving a suspicious transaction alert
These facts may support a finding that the transaction was authorized, that the user had actual or apparent permission, or that the cardholder contributed to the loss. But sharing an OTP or being deceived by a phishing message does not automatically settle the entire case. The issuer should still examine how the fraud occurred, whether warnings and authentication controls were adequate, and whether its monitoring systems reacted appropriately.
A transaction initially authorized by the cardholder is also not necessarily “unauthorized” merely because the goods were defective, the merchant failed to deliver, or the cardholder later regretted the purchase. Those situations ordinarily involve a merchant or contractual dispute and may follow a different chargeback process.
Supplementary cards
Charges made using a valid supplementary card are commonly charged to the primary account under the card agreement. If a supplementary cardholder exceeded private instructions from the primary cardholder, liability will depend on the agreement, the authority actually given, and what the issuer and merchant reasonably knew. Review the specific card terms before describing such a charge as unauthorized.
The credit-card issuer
An issuer may have to reverse or absorb an unauthorized charge when the evidence shows that the transaction occurred without the cardholder’s consent and responsibility properly lies with the issuer under the law, BSP rules, the card agreement, or applicable card-network procedures.
Under the Financial Products and Services Consumer Protection Act, Republic Act No. 11765, financial consumers have rights to protection against fraud and misuse and to timely complaint handling. Financial institutions must maintain appropriate information-security standards and provide a free consumer-assistance mechanism.
BSP consumer-protection regulations require supervised institutions to assess claims involving unauthorized transactions. Relevant considerations include:
- The cardholder’s actions before, during, and after the transaction
- Acts or omissions of the issuer, its employees, agents, outsourced entities, or service providers
- Whether the institution and its service providers complied with applicable security and consumer-protection requirements
The issuer should therefore conduct a real investigation. A response that merely says “the OTP was correct,” “the transaction was authenticated,” or “the merchant completed the charge” may not address all relevant issues.
While the final investigation is pending, Republic Act No. 11765 requires the financial service provider to suspend interest, fees, and charges connected with the disputed amount, or provide a similar reasonable accommodation.
The merchant or acquiring institution
Republic Act No. 10870 requires agreements between acquiring institutions and partner merchants to contain a requirement that merchants exercise due diligence in establishing the cardholder’s identity. An issuer may also verify a purchase when it has reasonable concern about the transaction’s validity.
A merchant’s failure to follow required verification, acceptance, or security procedures can affect who ultimately bears the charge under the parties’ contracts and card-network rules. It does not mean that every merchant automatically owes the cardholder a direct refund.
For online purchases, useful questions include whether the merchant:
- Used the required authentication process
- Retained proof of the order and delivery
- Shipped to an address inconsistent with the customer’s records
- Ignored obvious mismatches or fraud warnings
- Processed recurring charges without valid consent
- Continued charging after a cancellation took effect
The issuer and acquiring institution normally obtain this information through the dispute or chargeback process.
The rules vary by type of incident
| Situation | Starting legal position |
|---|---|
| Physical card lost or stolen; charge occurred before the issuer received the report | Generally for the cardholder’s account under Section 15 of Republic Act No. 10870 |
| Physical card lost or stolen; charge occurred after the issuer received prompt notice | Cardholder should not be liable for later unauthorized use |
| Card still in the cardholder’s possession but details were cloned or stolen | Requires investigation; the lost-or-stolen-card rule should not automatically decide the dispute |
| Account takeover, phishing, or unauthorized online purchase | Liability depends on consent, conduct, authentication evidence, and institutional security compliance |
| Cardholder knowingly gave another person the card, OTP, or account access | May be treated as authorized or as cardholder-contributed loss, depending on the facts |
| Valid purchase but goods were not delivered, were defective, or a refund was not processed | Usually a merchant or billing dispute rather than pure unauthorized-use fraud |
| Supplementary-card transaction | Usually governed by the primary-card agreement and the authority given to the supplementary cardholder |
| Credit card used to perform an electronic fund transfer | Additional electronic-transfer and anti-scam rules may apply; ordinary credit-card purchases are treated differently |
The temporary-holding mechanism under the Anti-Financial Account Scamming Act, Republic Act No. 12010, principally concerns disputed electronic fund transfers. Current BSP rules generally do not apply that holding mechanism to ordinary credit-card purchases, except insofar as a credit card is used to perform an electronic fund transfer through an automated clearing house.
What to do immediately
1. Contact the issuer through an official channel
Use the number printed on the card, the issuer’s official mobile app, or its verified website. Ask the issuer to:
- Block the affected card
- Stop further transactions
- Replace the card and number
- Secure or temporarily restrict the online account if compromised
- Record the exact date and time of your fraud report
- Open a formal dispute for every unauthorized charge
- Give you a case or reference number
- Explain what documents it requires
- Confirm how the disputed amount will be treated while investigated
If your phone or SIM was also compromised, contact your telecommunications provider immediately and secure your email and mobile accounts.
2. Submit a written dispute
Even if you first called, send a written complaint through the issuer’s official complaint channel. Identify each disputed transaction by:
- Transaction date and posting date
- Merchant name
- Amount and currency
- Last four digits of the card
- Reason it was not authorized
- Whether the card remained in your possession
- Whether you received, disclosed, or entered an OTP
- When and how you discovered the charge
- When and how you reported it
State the remedy you want, such as reversal of the disputed amount and removal of related interest, penalties, and fees.
3. Meet the statutory billing-dispute deadline
Under Section 18 of Republic Act No. 10870, issuers must allow cardholders up to 30 calendar days from the statement date to report a billing error or discrepancy. The issuer must take action within 10 business days after receiving the notice.
Do not treat 30 days as a waiting period. Report immediately even if the charge is still pending, then follow the issuer’s instructions for formally disputing it once posted. An issuer’s card agreement or chargeback rules may also contain operational deadlines, so earlier is safer.
4. Ask for suspension of charges
In the written dispute, invoke Republic Act No. 11765 and request that the issuer suspend interest, fees, and charges attributable to the disputed amount while its final investigation remains pending.
Ask how to pay the undisputed portion of the bill without being treated as admitting the disputed transaction. Do not simply ignore the entire statement, because legitimate purchases and other undisputed amounts may remain payable.
5. Secure every connected account
Change passwords using a trusted device. Start with the email account linked to the card, followed by the issuer’s app, online-shopping accounts, and mobile-wallet accounts. Use unique passwords and enable multi-factor authentication where available.
Remove the compromised card from shopping sites, delivery apps, browsers, mobile wallets, and subscription services. Review recent changes to contact information, device registrations, delivery addresses, and supplementary cards.
6. Notify the merchant when useful
For an identifiable merchant, report the fraud promptly and ask it to preserve the order, account, device, delivery, and communications records. Do not rely on the merchant report as a substitute for notifying the issuer.
7. Report apparent criminal activity
For fraud, identity theft, skimming, account hacking, or an identifiable unauthorized user, consider reporting to the Philippine National Police, National Bureau of Investigation, or Cybercrime Investigation and Coordinating Center. Bring the transaction records and your issuer’s case number.
A police or cybercrime report can support the investigation, but the issuer should not refuse to receive a timely card dispute merely because no criminal case has yet been completed.
Evidence to preserve
Keep original electronic files where possible, not only edited screenshots. Preserve:
- Complete statements of account
- Transaction alerts and their timestamps
- SMS messages and OTP records
- Emails, including full headers if phishing is suspected
- Call logs and recordings lawfully in your possession
- Fraud-report reference numbers
- Copies of complaints and issuer responses
- Screenshots of account activity and device notifications
- Proof that the card was with you
- Receipts showing where you were at the relevant time
- Merchant order, IP, device, billing, and delivery information
- Proof of SIM loss, replacement, or porting
- Evidence of password or contact-detail changes
- Police, NBI, or cybercrime reports
- The card agreement and applicable terms at the time of the incident
Do not post complete card numbers, OTPs, passwords, IDs, or unredacted statements on social media. When escalating a complaint, provide sensitive information only through verified secure channels and redact information that is not needed.
What to request from the issuer’s investigation
Ask for a written, transaction-specific explanation. Depending on the type of charge, relevant records may include:
- Authentication method used
- OTP generation, delivery, and validation timestamps
- Destination mobile number or authentication channel
- Device-registration and device-change records
- Login and risk-monitoring events
- Merchant category and transaction channel
- Whether the physical chip, magnetic stripe, contactless function, or manually entered card details were used
- 3-D Secure or comparable authentication results
- Address-verification or security-code results
- Fraud alerts and the issuer’s response
- Merchant proof of order, service, or delivery
- The basis for concluding that the cardholder consented
Some information may be withheld or redacted for security, privacy, or investigative reasons. Even so, the issuer should explain the material basis of its decision clearly enough for the cardholder to understand and challenge it.
If the issuer denies the dispute
First, request reconsideration through the issuer’s Financial Consumer Protection Assistance Mechanism. Address the stated reasons one by one and attach any missing evidence.
If the response remains unsatisfactory, escalate the complaint to the Bangko Sentral ng Pilipinas. The BSP Consumer Assistance Mechanism is a second-level remedy, so you should ordinarily complain to the issuer first and preserve its response or proof that it failed to act.
The BSP accepts complaints through its BSP Online Buddy and the alternatives listed on its official Consumer Assistance Channels and Chatbot page. The page currently lists:
- Email:
consumeraffairs@bsp.gov.ph - Telephone:
(02) 5306-2584 - Mail and walk-in channels stated on the BSP page
Include a concise timeline, the remedy requested, your complaint to the issuer, the issuer’s answer, and supporting documents. Do not send your PIN, password, OTP, or complete credit-card number.
BSP consumer assistance facilitates communication and possible resolution. Depending on the dispute and applicable jurisdictional requirements, mediation, formal BSP adjudication, or a court action may also be available. Filing requirements and procedural deadlines should be checked when relief beyond ordinary complaint handling is contemplated.
Common mistakes that weaken a claim
- Waiting for the next statement before reporting
- Reporting only to the merchant and not to the issuer
- Cancelling the card without separately disputing each charge
- Losing the report reference number or proof of notice
- Saying only “I did not make this” without providing a timeline
- Deleting phishing messages, OTPs, alerts, or account records
- Paying the disputed amount without stating that payment is under protest
- Withholding facts about a shared card, shared device, or disclosed OTP
- Assuming a police report automatically produces a refund
- Assuming use of an OTP automatically proves consent
- Ignoring legitimate portions of the bill
- Posting sensitive evidence publicly
- Missing the 30-calendar-day billing-dispute period
When legal help is urgent
Consult a Philippine lawyer promptly if:
- The disputed amount is substantial
- The issuer threatens collection or litigation
- Your credit record is being affected
- You received a demand letter, summons, subpoena, or court document
- The issuer alleges that you participated in the fraud
- A family member, employee, supplementary cardholder, or business partner is implicated
- The compromise involved identity theft or multiple financial accounts
- The issuer refuses to suspend charges or conduct a meaningful investigation
- Important electronic evidence may soon be deleted
- A BSP proceeding, mediation, adjudication, or court filing is being considered
Court and regulatory remedies can have separate filing periods. Do not assume that an internal investigation pauses every prescriptive or procedural deadline.
FAQ
Am I automatically liable because an OTP was used?
No. OTP use is relevant evidence, but the issuer should still determine who obtained or entered it, whether you knowingly approved the transaction, whether your device or SIM was compromised, and whether the issuer’s security controls complied with applicable requirements.
What if I was tricked into giving the OTP?
That fact may be considered in allocating the loss, but it does not eliminate the issuer’s duty to investigate. Explain exactly what the fraudster said, what screen or message you saw, and what you believed you were authorizing. Preserve the messages and call records.
What if the card never left my possession?
State that clearly. The transaction may involve stolen card details, cloning, account takeover, a compromised merchant, or another card-not-present method rather than a lost or stolen physical card.
Do I have to pay the disputed charge while the investigation is pending?
Republic Act No. 11765 requires the provider to suspend interest, fees, and charges on an alleged disputed amount or unauthorized transaction while its final investigation is pending, or provide a similar reasonable accommodation. Confirm the arrangement in writing and continue paying legitimate, undisputed amounts as required.
Can the bank reject my complaint because I have no police report?
The issuer should receive and investigate a timely financial complaint through its consumer-assistance mechanism. A police report may strengthen the evidence or be requested for fraud processing, but criminal prosecution and the billing dispute are distinct processes.
Is the merchant automatically liable for accepting the fraudulent charge?
No. Merchants have verification and due-diligence responsibilities, but the final allocation of the loss depends on the evidence, applicable contracts, and card-network procedures. The cardholder should ordinarily dispute the charge through the issuer rather than trying to determine the merchant’s liability alone.
What if I know the person who used the card?
Report the transaction truthfully and preserve proof that permission was not given or had been withdrawn. If you previously allowed that person to use the card, the scope and withdrawal of authority may become central issues. Consider legal advice before making accusations in a family, employment, or business dispute.
Can I wait until the issuer completes its investigation before going to the BSP?
You must normally use the issuer’s complaint mechanism first. If its response is unsatisfactory or the matter remains unresolved, you may elevate it through the BSP’s official consumer-assistance channels. Do not let escalation cause you to miss other applicable deadlines.
Official legal references
- Republic Act No. 10870 — Philippine Credit Card Industry Regulation Law
- Republic Act No. 11765 — Financial Products and Services Consumer Protection Act
- Republic Act No. 8484 — Access Devices Regulation Act
- Republic Act No. 11449 — Amendments concerning access-device fraud
- Republic Act No. 12010 — Anti-Financial Account Scamming Act
- BSP Financial Consumer Protection Framework
- BSP Consumer Assistance Channels
- Aznar v. Citibank, N.A., G.R. No. 135149, July 25, 2006
This article provides general Philippine legal information, not advice for a particular dispute. Liability may turn on the card agreement, transaction records, authentication evidence, and the parties’ conduct. Official sources and procedures were checked as of September 3, 2026.